Legal support for IT companies: SLA, NDA, sources and hidden risks

12.01.20264 min read
Meshcheryakov Dmitry
SEO specialistMeshcheryakov Dmitry

In the IT industry, code and product architecture are the main assets. However, many web studios, integrators and outsourcing agencies still work according to template “fish” contracts from Google, where a website is assessed according to the same legal standards as laying bricks at a construction site.

Such carelessness often leads to cash gaps, lawsuits with customers due to “blurred” technical specifications, and demands to return 100% of the advance payment after six months of development due to the fact that “the client didn’t like the color of the buttons”.

Qualitative legal support for the IT industry is the protection of intellectual property, money and processes. Let's figure out what it consists of.


1. The holy trinity of documents for an IT company

If you develop software or custom websites (Software Development), your business is based on three fundamental documents. And they must be unique to your business model.

Software Development Agreement (Copyright Agreement / Mixed Agreement)

This is no ordinary contract. The contract must clearly state:

  • Iterativeness (Agile/Sprints) vs Waterfall: Как оплачивается разработка? За часы (Time & Material) или за фиксированный объем (Fixed Price)?
  • Acceptance procedure: If the customer remains silent 10 days after the frontend acceptance certificate, the work is considered accepted unilaterally. (Without this point, you will be chasing clients for months).
  • Moment of transfer of rights: Exclusive rights to the written code are transferred to the customer only after 100% payment. If there is no payment, the code legally belongs to the studio.

NDA (Non-Disclosure Agreement)

The NDA must be two-layered.

  • External: With the customer. Protects your unique work methodology, estimates and stack.
  • Internal: With programmers and freelancers. A developer employee does not have the right to take pieces of code from your project, post them on his public GitHub, or sell the architecture to the customer’s competitors.

SLA (Service Level Agreement)

Service Level Agreement for the technical support phase. If a client's website crashes at 2:00 am on a Saturday, are you required to jump out of bed and fix it? SLA strictly fixes:

  • Response time to tickets (for example, 2 hours during business hours).
  • Bug priorities (Critical/minor).
  • Communication channel (strictly through the Jira/Redmine bug tracker, and not voice messages on WhatsApp).

2. Intellectual Property (IP) Protection

Freelance developer Vasya wrote a custom filtering module for an online store for your studio, you handed over the project to the customer, and tomorrow Vasya sued you and the customer for violating his copyright. Sounds absurd? These are the realities of the Civil Code of the Russian Federation (Part 4).

Copyright always initially accrues to the individual (the person who wrote the code). The lawyer must trace the mechanism of “alienation” of these rights:

  1. If Vasya is on staff: the contract must contain the wording about “Work of Service”, plus a written technical specification is required.
  2. If Vasya is a freelancer: GPC agreement with a mandatory act of acceptance and transfer of exclusive rights.

Without this chain, your IT company sells air to the customer. The client may become a hostage to the freelancer, who will later demand royalties.


3. Licensing and SaaS models

If a company moves from outsourcing (coding to order) to a product (selling a subscription to its cloud CRM or parser), the legal framework changes completely. There is a need for EULA (End User License Agreement) and license/sublicense agreement.

The lawyer must take into account the inclusion of your product in Register of domestic software (Ministry of Digital Development) so that you receive 0% VAT, and also make sure that the third-party libraries you use internally (Open Source, for example, under GPL or MIT licenses) do not force you to make your proprietary code publicly available. It's called a Copyleft infection, and it's ruining startups.


How to choose a competent IT lawyer?

Master of divorce proceedings or real estate transactions can't draw up a high-quality contract for blockchain development. The IT sector has its own complex glossary and risk architecture.

Criteria for choosing a lawyer / legal boutique:

  1. Understands the difference between SaaS, On-Premise, PaaS. Knows the difference between a backend and a frontend, and an API from a DBMS (this is necessary for writing specifications and technical specifications so that they have legal weight in court).
  2. Fluent in Open Source licenses (MIT, Apache, GPL).
  3. Practices GDPR DPA (Data Processing Agreement) and transnational contracts if you outsource to the West or Asian countries.

Free SEO audit of your website

Leave a request and our specialists will find areas of search traffic growth.

Summary

A strong lawyer for an IT company is not a person who sorts out the consequences of lawsuits, but an architect who makes the occurrence of such lawsuits impossible thanks to reinforced concrete contracts.

Do you want your web project worked like clockwork not only technically, but also legally? At NBM-IT we combine deep engineering expertise with an understanding of business risks. We build web ecosystems ready for high loads and the most stringent compliance checks.

Leave your contacts - we will call you back, sort out the problem and offer the best way. We have more than 350 projects behind us, each of which we launched with an individual approach. We guarantee expert advice during business hours.